(Aster)-picking through the pieces of short URL services
An investigation into the maliciousness of short URLs
Robert Diepeveen & Peter Boers 2016
(Aster)-picking through the pieces of short URL services An - - PowerPoint PPT Presentation
(Aster)-picking through the pieces of short URL services An investigation into the maliciousness of short URLs Robert Diepeveen & Peter Boers 2016 Motivation Obfuscation Brute force Uniform sample Contributions:
Robert Diepeveen & Peter Boers 2016
– Comparison between services – Observation of locality based adware network
– Which service provides proportionally the most
– What properties can be observed in encountered
– TinyURL – bitly – goo.gl
– Malware – Phishing – “Unwanted”
– Domain blacklist – IP blacklist
– PhishTank
– Creation date – Clicks – Referrers
– SSL info – Malicious classification – Server Headers (Last Modified, Server, Status Code) – Script links – Page Size
– Bitly: 3.5 trillion, max 7 – TinyURL: 80 billion, max 7 – Goo.gl: 58 billion, max 6
– Except goo.gl
– 8,52 Mbit/s out – 2,44 Mbit/s in
– TinyURL: 1,39 million visited. – Bitly: +/- 6 K visited. – Goo.gl: +/- 4K visited.
– TinyURL: 946 – Bitly: 2 – Goo.gl: 0
– video.asterpix.com/v/<ID>/<Title>/ – www.asterpix.com/console/?avi=<ID>
– Asia – America – Europe
– Entry – Redirection – Hand off
– Where is the visitor from? – Has he visited in the past?
– Typical JS redirection to obfuscate paths – All over the world and at least 4 hops – Depending on location of visitor
– Catered to the visitor in language and offering
– Surveys – “Free” money – Vouchers
– park.above.com – bidr.trellian.com – z[a-z].zeroredirect.com
– Unable to see if this is actively abused
– Block secondary/tertiary redirectors.